The news
Device code phishing and other token-theft kits have been linked to account compromises at thousands of organizations in 2026 despite multifactor authentication (MFA), according to research published in September by Microsoft, eSentire and CloudSEK. The kits capture the sign-in tokens issued after MFA succeeds, so passwords alone are not what attackers need.
The largest case is EvilTokens. On September 22, Microsoft (MSFT) said its Digital Crimes Unit had obtained a court order in the U.S. District Court for the Eastern District of Virginia to seize 50 websites and disable more than 150 supporting domains. Microsoft said the service, launched in February 2026, had been linked to more than 12,000 compromised email inboxes at over 10,000 organizations, and was sold on Telegram for a $1,500 setup fee plus a $500 monthly subscription. Microsoft said the Metropolitan Police arrested two men, aged 32 and 38, in the U.K. on September 11 on suspicion of offenses linked to allegedly running EvilTokens; both were released on police bail, with no charges reported.
EvilTokens relied on device code phishing, which abuses the OAuth 2.0 device authorization grant, a legitimate sign-in standard for input-limited devices such as smart TVs. Victims enter a code on the real Microsoft login page, complete MFA, and unknowingly grant the attacker access. Microsoft said the service's AI chatbot could then analyze a victim's inbox to spot trusted relationships and payment authorizations and suggest fraud strategies.
eSentire's September 15 analysis of a separate kit, GhostCode, shows the speed involved. Attackers posed as procurement officers, sent password-protected files through WeTransfer, and steered victims to a device code prompt. After the victim signed in, the attackers began enrolling devices in Microsoft Intune within five seconds, obtained a Primary Refresh Token within 32 seconds, and had three devices registered within 78 seconds. eSentire said such tokens enable single sign-on across a tenant and persist for up to 14 days.
A third service used a different route to the same result. CloudSEK, which gained access to the BigBear 2.0 control panel, found completed MFA bypasses at 258 organizations and more than 5,000 stolen credential records, BleepingComputer reported on September 7. BigBear used an adversary-in-the-middle proxy that relays the real login page, and custom code that disabled FIDO2 security key sign-in to force weaker methods.
The numbers
- Compromised inboxes linked to EvilTokens
- 12,000+
- Organizations linked to EvilTokens compromises
- 10,000+
- EvilTokens price
- $1,500 setup + $500/month
- GhostCode time to Primary Refresh Token
- 32 seconds
- Organizations with BigBear MFA bypass
- 258
Why CEOs should care
For CISOs, the fixes are specific. eSentire, like Microsoft's security researchers, recommends blocking the device code sign-in flow through Conditional Access for everyone except the few users and devices that genuinely need it. eSentire also advises requiring managed, compliant devices for access, and alerting when one session registers several devices. CloudSEK's advice after BigBear is to revoke sessions and refresh tokens, not just reset passwords, and to enforce FIDO2 or WebAuthn security keys and passkeys, which bind sign-in to the real website and defeat proxy pages.
For CFOs and controllers, the EvilTokens chatbot was built to find payment workflows inside stolen mailboxes. Microsoft advises checking any request to alter payment details or make an unusual transfer through a second, trusted means of contact. Make that a written control with named owners, and test it with finance staff and key suppliers.
For boards, ask two questions: what share of employees can still sign in with methods that a phishing kit can relay, and how quickly can the security team revoke every token for a compromised account? If the answers are unclear, identity should be on the next audit committee agenda.
The bigger picture
The pattern is commercialization. Subscription pricing, affiliate operators and AI features turn token theft into a service that low-skill criminals can rent. Against proxy kits, Google Threat Intelligence Group's August report on the extortion group UNC6671, which paired phone-based social engineering with adversary-in-the-middle pages, recommends phishing-resistant authenticators, which work only on the genuine website. That does not stop device code phishing, where victims sign in on Microsoft's own page.
The targets matter too. Microsoft listed wholesale distribution, construction, financial services, real estate, higher education and healthcare among the sectors EvilTokens targeted, and GhostCode's operators posed as buyers approaching sales teams. These are businesses that move money and sign deals on the strength of email, which is exactly where a hijacked inbox pays off.
What’s next
Expect more takedowns like Microsoft's, which it called its 40th court-authorized disruption, and more kits that target whatever sign-in flows remain open. Watch Microsoft's default policies for device code authentication, and whether cyber insurers begin asking about phishing-resistant MFA coverage at renewal.
What “Fact-checked” means
Fact-checking means testing a story’s facts against the evidence before it is published. This story went through at least two separate checks before this version was published.
- What we checked
- Its names, figures, dates, job titles, quotes and who said what were checked against the story’s sources, including its main source where it could be opened. The headline was checked for accuracy and overstatement.
- How
- A first check reviewed the whole story. If it passed, a second, skeptical check went back to the sources to look for mistakes in the most important facts. If a check flagged the story, it was edited to fix the problems found, and a separate re-check then reviewed the whole story again.
- Who
- The checks are made by our newsroom, as steps kept separate from the writing, under rules set by our editor, Hussein Mukhtar. A story the checks still flag is held for the editor, who decides whether it is fixed, published or dropped.
- If something is wrong
- “Fact-checked” does not mean error-free. If a material error is found after publication, we correct the story and add a note saying what changed. Report an error
Companies in this story








